Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update to OSV-Scanner v2 for vulnerability scanning #779

Draft
wants to merge 1 commit into
base: main
Choose a base branch
from
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 9 additions & 8 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -116,11 +116,14 @@ scan-go-nancy:
go list -json -deps '$(go_dir)/...' | nancy sleuth

.PHONY: scan-go-osv-scanner
scan-go-osv-scanner:
go install github.com/google/osv-scanner/cmd/osv-scanner@latest
scan-go-osv-scanner: install-osv-scanner
echo "GoVersionOverride = '$$(go env GOVERSION | sed 's/^go//')'" > osv-scanner.toml
osv-scanner scan --lockfile='$(base_dir)/go.mod' || [ \( $$? -gt 1 \) -a \( $$? -lt 127 \) ]

.PHONY: install-osv-scanner
install-osv-scanner:
go install github.com/google/osv-scanner/v2/cmd/osv-scanner@latest

.PHONY: scan-node
scan-node: scan-node-npm-audit scan-node-osv-scanner

Expand All @@ -131,12 +134,11 @@ scan-node-npm-audit:
npm audit --omit=dev

.PHONY: scan-node-osv-scanner
scan-node-osv-scanner:
go install github.com/google/osv-scanner/cmd/osv-scanner@latest
scan-node-osv-scanner: install-osv-scanner
cd '$(node_dir)' && \
npm install --omit=dev --package-lock-only --no-audit && \
npm sbom --omit=dev --package-lock-only --sbom-format cyclonedx > sbom.json && \
osv-scanner scan --sbom=sbom.json
npm sbom --omit=dev --package-lock-only --sbom-format cyclonedx > bom.cdx.json && \
osv-scanner scan --sbom=bom.cdx.json

.PHONY: scan-java
scan-java: scan-java-dependency-check scan-java-osv-scanner
Expand All @@ -147,8 +149,7 @@ scan-java-dependency-check:
mvn dependency-check:check -P owasp

.PHONY: scan-java-osv-scanner
scan-java-osv-scanner:
go install github.com/google/osv-scanner/cmd/osv-scanner@latest
scan-java-osv-scanner: install-osv-scanner
osv-scanner scan --lockfile='$(java_dir)/pom.xml'

.PHONY: install-mockery
Expand Down
2 changes: 1 addition & 1 deletion node/.gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -4,4 +4,4 @@ coverage/
*.tgz
src/protos/
apidocs/
sbom.json
*.cdx.json